> Source: [sk172744](https://support.checkpoint.com/results/sk/sk172744)

# sk172744 - In 1500 appliances: When a 3rd-party VPN peer uses LDAP as its CRL DP protocol, CRL fetch is not done correctly resulting in VPN failures

| Property | Value |
|----------|-------|
| Solution ID | sk172744 |
| Date Created | 2021-03-25 |
| Last Modified | 2022-07-13 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |
| Platform | 1500 |

## Symptoms

- * In 1500 appliances: When a 3rd-party VPN peer uses LDAP as its CRL DP protocol, CRL fetch is not done properly, resulting in VPN failures.
* *sfwd.elg* shows this error:   
  \[sfwd\] ExternalCrlFetchSingleton::asyncCallback: dp in front of queue: CN=xxxx,O=xxxx,C=xx   
  \[sfwd 4700 4156121104\]@\[Gateway Name\]\[31 Jan 10:22:48\] ExternalCrlFetchSingleton::asyncCallback: calling cb_external with 0 asearch: xxxxxxx  
  \[sfwd 4700 4156121104\]@\[Gateway Name\]\[31 Jan 10:22:48\] fwFetchCRL_cb_external: fail  
  \[sfwd 4700 4156121104\]@\[Gateway Name\]\[31 Jan 10:22:48\] fwFetchCRL_cb: begin  
  \[sfwd 4700 4156121104\]@\[Gateway Name\]\[31 Jan 10:22:48\] fwFetchCRL_cb: Entering for dp: CN=xxxx,O=xxxx,C=xx  
  \[sfwd 4700 4156121104\]@\[Gateway Name\]\[31 Jan 10:22:48\] fwFetchCRL_cb: Fetch failed

  <br />

## Cause

The relevant code, which loads LDAP-related configuration before it attempts to fetch the CRL, was not called correctly.

<br />

## Solution

**This problem was fixed. The fix is included in:**

* **[R80.20.25 Quantum Spark](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk171824)**

If you do not wish to upgrade, [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix. For faster resolution and verification please collect CPinfo files from the Security Management and Security Gateways involved in the case.

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
